<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-13462206.comments</id><updated>2012-01-05T11:56:12.494+01:00</updated><category term='Livo'/><category term='Biométrie'/><category term='XML SAML OpenID Windows CardSpace User'/><category term='Strong Authentication'/><category term='Clavid Yubico OpenID'/><category term='Usurpation d&apos;identité'/><category term='Ethical Technologies Identity Geneva Unesco'/><category term='PEM'/><category term='Biométrie Iris'/><category term='Reprise'/><category term='XML SOAP SAML WS-Signature WS-Encryption'/><category term='OpenID Authentification Forte'/><category term='Risk Based Authentication'/><category term='PingIdentity'/><category term='OCRA'/><category term='Insecure Keylogger'/><category term='Private Key X509 PKI IE exploit'/><category term='Vol identités numériques'/><category term='ANSI'/><category term='Identity'/><category term='Coffre forte électronique'/><category term='Attacks MiM DH OpenID Authentification Forte'/><category term='base64'/><category term='PCI-DSS'/><category term='RSA PKI X509'/><category term='PKI Biométrie Match on Card OCSP'/><category term='Identity Theft'/><category term='EMV-CAP'/><category term='Identités numérique'/><category term='eToken Authentification Forte'/><category term='Mots de passe'/><category term='Fingerprint reader MS bypass Microsoft'/><category term='OpenID David Recordon'/><category term='Authentification forte'/><category term='Sxip'/><category term='Crack Password Authentification forte Wireless Keyboard'/><category term='Munities Biométrie'/><category term='SAML PKI idp Digital ID Identity'/><category term='Sniffer'/><category term='http://www.portknocking.org/'/><category term='Web 2.0 Identités numériques Empreinte numérique'/><category term='SMS'/><category term='Infocard Cardspace'/><category term='MOC'/><category term='SSH'/><category term='DNA'/><category term='Check Point User Conference'/><category term='trustbearer.com'/><category term='Personal Portable Security Device'/><category term='FFR'/><category term='TPM'/><category term='brute force'/><category term='SMS OTP Certificat'/><category term='Out of Band Authentication'/><category term='OATH OTP SmartCard ICT'/><category term='CAPTCHA'/><category term='openssl'/><category term='IDSP'/><category term='XML'/><category term='Authentification Forte H1N1 Grippe A VPN SSL VPN IPSEC'/><category term='ID Selector OpenID'/><category term='smartphone'/><category term='FAR'/><category term='Xiring'/><category term='Mobile OTP'/><category term='OpenID'/><category term='Man-in-the-Browser'/><category term='CSR'/><category term='OpenID  Biometry'/><category term='MitB'/><category term='Digital ID OpenID Microsoft Open Specification Promise'/><category term='NTX'/><category term='OAUTH OpenID'/><category term='Identités numériques'/><category term='identityblog'/><category term='Webilus'/><category term='Authentication forte'/><category term='New Intrusion Tolerance Technology Treats Attacks as Inevitable'/><category term='OpenID Certificat Authentification Forte'/><category term='CRL'/><category term='Yubico'/><category term='Theft Prevention'/><category term='DDOS'/><category term='Pumpkin Hash'/><category term='OpenSSH'/><category term='SSTIC'/><category term='LASEC'/><category term='Cryptographic Filesystems'/><category term='Match on Card'/><category term='HSPD-12 PKI SAML'/><category term='The Tao of Authentication'/><category term='SSTIC 2009'/><category term='Iphone'/><category term='SecurID'/><category term='MITM'/><category term='Facebook OpenID'/><category term='OATH'/><category term='ISO'/><category term='Banana Security Biométrie Biometry'/><category term='Banker'/><category term='ANSI 378'/><category term='ADN'/><category term='Phone Factor'/><category term='Token USB'/><category term='Identité numérique'/><category term='Extended Validation'/><category term='Keyboard'/><category term='identité 2.0'/><category term='Avatar'/><category term='2FA'/><category term='L&apos;identité numériquelien technologique  entité réelle entité virtuelle'/><category term='Kim Cameron'/><category term='e-Xpert Solutions'/><category term='EMV'/><category term='Verayo'/><category term='SAML SSO'/><category term='OTP'/><category term='Biométrie Mobilité Authentification Forte'/><category term='ANSI-BBB Identity'/><category term='EPFL'/><category term='Bankers'/><category term='EV Certificate'/><category term='UPEK'/><category term='Définition'/><category term='Cold Boot Attacks'/><category term='Keepass'/><category term='TEXT'/><category term='Certificat'/><category term='Veine Biométrie'/><category term='HOTP'/><category term='3D-secure'/><category term='Crypto'/><category term='The Information Card Foundation'/><category term='PIP X509 OTP OpenID'/><category term='MD6'/><category term='Biométrie USA'/><category term='Keylogger'/><category term='PCI'/><category term='Identitité numérique'/><category term='Confiance'/><category term='RCA'/><category term='PAPE OpenID'/><category term='OpenID Facebook Google'/><category term='Active Directory Root PKI'/><category term='DLP'/><category term='OpenID Clavid SSL Client Certificate'/><category term='Biométrie Match on Card Veine Sony'/><category term='Citadelle Electronique Sylvain Maret'/><category term='FAST'/><category term='Match on Card Biométrie Authentification Forte PKI'/><category term='WS SOAP XML Axis'/><category term='ASF-WS'/><category term='wikipedia'/><category term='X509'/><category term='TOTP'/><category term='Strong Authentication; RSA; PKI; X509; SecurID; OTP; HOTP; TOTP; OpenID; OWASP; OATH; FFIEC'/><category term='EMV CAP Authentification Forte'/><category term='HSPD-12'/><category term='PKI'/><category term='eBanking Sécurité Authentification Forte'/><category term='SecurID; Hack; RSA; OTP; Seed; OATH'/><category term='Citizen ID Forum'/><category term='FIPS-201'/><category term='Checkpoint'/><category term='Vascular Pattern Recognition'/><category term='SAML OpenID PAPE'/><category term='saml'/><category term='Smartcard'/><category term='Botnet'/><category term='RFID'/><category term='Biométrie AD Microsoft'/><category term='SMS OATH Mobile'/><category term='Reconstructing Fingerprints from Minutiae Points'/><category term='Cardspace vs OpenID'/><category term='Yubikey'/><category term='OWASP OpenID'/><category term='DOS'/><title type='text'>La Citadelle Electronique:  Identité Numérique et Authentification Forte</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.citadelle-electronique.net/feeds/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/comments/default'/><link rel='alternate' type='text/html' href='http://www.citadelle-electronique.net/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/comments/default?start-index=26&amp;max-results=25'/><author><name>Sylvain Maret</name><uri>http://www.blogger.com/profile/04336297227186666432</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://3.bp.blogspot.com/_QntNf2b8LN8/SvG_8y8U6DI/AAAAAAAAHcg/k31ODCy9euU/S220/sylvain+cool+3.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>92</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-13462206.post-5831874988583060529</id><published>2012-01-05T10:16:38.699+01:00</published><updated>2012-01-05T10:16:38.699+01:00</updated><title type='text'>Sylvain,

Il semble cette solution soit la solutio...</title><content type='html'>Sylvain,&lt;br /&gt;&lt;br /&gt;Il semble cette solution soit la solution &amp;quot;miracle&amp;quot;, mais j&amp;#39;aurais quelques remarques:&lt;br /&gt;- mettre en place ce genre de sécurité à un cout&lt;br /&gt;- pour que cela soit valable il faut que tout le monde possède ce système&lt;br /&gt;- dans le domaine bancaire introduire un équipement electronique ou informatique devient compliqué.&lt;br /&gt;&lt;br /&gt;Je me permet ce commentaire car nous sommes en cours de réflexion sur cette problèmatique de remplacement de nos tokens et il semble qu&amp;#39;il n&amp;#39;ai pas de solution miracle, le token reste la solution la plus adapté.&lt;br /&gt;&lt;br /&gt;Qu&amp;#39;en pensez-vous?&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;GM</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/8107184206302504635/comments/default/5831874988583060529'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/8107184206302504635/comments/default/5831874988583060529'/><link rel='alternate' type='text/html' href='http://www.citadelle-electronique.net/2011/07/piratage-rsa-securid-par-francois.html?showComment=1325754998699#c5831874988583060529' title=''/><author><name>GM</name><uri>http://www.blogger.com/profile/06020956853973623303</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.citadelle-electronique.net/2011/07/piratage-rsa-securid-par-francois.html' ref='tag:blogger.com,1999:blog-13462206.post-8107184206302504635' source='http://www.blogger.com/feeds/13462206/posts/default/8107184206302504635' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-2054739257'/></entry><entry><id>tag:blogger.com,1999:blog-13462206.post-7893399332638963727</id><published>2011-07-20T21:34:15.316+02:00</published><updated>2011-07-20T21:34:15.316+02:00</updated><title type='text'>C&amp;#39;est un peu comme si les informaticiens se me...</title><content type='html'>C&amp;#39;est un peu comme si les informaticiens se mettaient à faire du journalisme... &lt;br /&gt;La sensibilisation à la sécurité des systèmes d&amp;#39;information est indispensable. En ce sens, on ne peut que remercier la télévision d&amp;#39;avoir tenter de communiquer sur le sujet! Malheureusement, le scénario était mal choisi.&lt;br /&gt;La démocratisation de sujet aussi pointu techniquement reste également un vrai challenge pour les responsables sécurité!&lt;br /&gt;Qui sait, peut-être qu&amp;#39;un jour les campagnes de sensibilisation à la sécurité feront monter l&amp;#39;audimat ;-)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/7470105899340163707/comments/default/7893399332638963727'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/7470105899340163707/comments/default/7893399332638963727'/><link rel='alternate' type='text/html' href='http://www.citadelle-electronique.net/2011/07/quand-la-tele-se-lance-dans-laudit.html?showComment=1311190455316#c7893399332638963727' title=''/><author><name>pascal.fontaine</name><uri>http://pascal.fontaine.clavid.ch/</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/openid16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.citadelle-electronique.net/2011/07/quand-la-tele-se-lance-dans-laudit.html' ref='tag:blogger.com,1999:blog-13462206.post-7470105899340163707' source='http://www.blogger.com/feeds/13462206/posts/default/7470105899340163707' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1815802030'/></entry><entry><id>tag:blogger.com,1999:blog-13462206.post-1681734550259903947</id><published>2011-07-20T21:22:10.307+02:00</published><updated>2011-07-20T21:22:10.307+02:00</updated><title type='text'>Effectivement ce reportage a fait couler beaucoup ...</title><content type='html'>Effectivement ce reportage a fait couler beaucoup d&amp;#39;encre.&lt;br /&gt;&lt;br /&gt;Les mauvaises langues iront jusqu&amp;#39;à dire que le seul système qui n&amp;#39;a pas été compromis par les experts de l&amp;#39;EPFZ est celui de l&amp;#39;UBS, mis au point par l&amp;#39;UBS avec des experts de... l&amp;#39;EPFZ!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/7470105899340163707/comments/default/1681734550259903947'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/7470105899340163707/comments/default/1681734550259903947'/><link rel='alternate' type='text/html' href='http://www.citadelle-electronique.net/2011/07/quand-la-tele-se-lance-dans-laudit.html?showComment=1311189730307#c1681734550259903947' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.citadelle-electronique.net/2011/07/quand-la-tele-se-lance-dans-laudit.html' ref='tag:blogger.com,1999:blog-13462206.post-7470105899340163707' source='http://www.blogger.com/feeds/13462206/posts/default/7470105899340163707' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-944790170'/></entry><entry><id>tag:blogger.com,1999:blog-13462206.post-5769856180392077946</id><published>2011-07-06T23:29:36.562+02:00</published><updated>2011-07-06T23:29:36.562+02:00</updated><title type='text'>Thanks Dug, I will have a look

Sylvain</title><content type='html'>Thanks Dug, I will have a look&lt;br /&gt;&lt;br /&gt;Sylvain</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3992226397490897300/comments/default/5769856180392077946'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3992226397490897300/comments/default/5769856180392077946'/><link rel='alternate' type='text/html' href='http://www.citadelle-electronique.net/2011/06/furtivite-et-hardening-avec-un.html?showComment=1309987776562#c5769856180392077946' title=''/><author><name>smaret</name><uri>http://smaret.clavid.ch/</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='15908526881261538232'/><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/openid16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.citadelle-electronique.net/2011/06/furtivite-et-hardening-avec-un.html' ref='tag:blogger.com,1999:blog-13462206.post-3992226397490897300' source='http://www.blogger.com/feeds/13462206/posts/default/3992226397490897300' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-799738138'/></entry><entry><id>tag:blogger.com,1999:blog-13462206.post-3395124157076164540</id><published>2011-07-06T16:25:21.606+02:00</published><updated>2011-07-06T16:25:21.606+02:00</updated><title type='text'>This is an old exploit in OPIE, the one-time passw...</title><content type='html'>This is an old exploit in OPIE, the one-time password library on FreeBSD, not OpenSSH. See http://seclists.org/fulldisclosure/2011/Jul/0 and http://site.pi3.com.pl/adv/libopie-adv.txt&lt;br /&gt;&lt;br /&gt;For a better two-factor implementation for OpenSSH (that works with pubkey auth as well - PAM does not), check out http://www.duosecurity.com&lt;br /&gt;&lt;br /&gt;Full disclosure: I&amp;#39;m a co-founder of Duo Security - and an OpenSSH author. :-)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3992226397490897300/comments/default/3395124157076164540'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3992226397490897300/comments/default/3395124157076164540'/><link rel='alternate' type='text/html' href='http://www.citadelle-electronique.net/2011/06/furtivite-et-hardening-avec-un.html?showComment=1309962321606#c3395124157076164540' title=''/><author><name>Dug</name><uri>http://www.blogger.com/profile/02438933976359733399</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.citadelle-electronique.net/2011/06/furtivite-et-hardening-avec-un.html' ref='tag:blogger.com,1999:blog-13462206.post-3992226397490897300' source='http://www.blogger.com/feeds/13462206/posts/default/3992226397490897300' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-822540053'/></entry><entry><id>tag:blogger.com,1999:blog-13462206.post-5261832063548407484</id><published>2011-06-30T18:25:54.827+02:00</published><updated>2011-06-30T18:25:54.827+02:00</updated><title type='text'>Pour confirmer cela:

OpenSSH 3.5p1 Remote Root Ex...</title><content type='html'>Pour confirmer cela:&lt;br /&gt;&lt;br /&gt;OpenSSH 3.5p1 Remote Root Exploit For FreeBSD http://packetstormsecurity.org/files/102683 #exploit</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3992226397490897300/comments/default/5261832063548407484'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3992226397490897300/comments/default/5261832063548407484'/><link rel='alternate' type='text/html' href='http://www.citadelle-electronique.net/2011/06/furtivite-et-hardening-avec-un.html?showComment=1309451154827#c5261832063548407484' title=''/><author><name>smaret</name><uri>http://smaret.clavid.ch/</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='15908526881261538232'/><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/openid16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.citadelle-electronique.net/2011/06/furtivite-et-hardening-avec-un.html' ref='tag:blogger.com,1999:blog-13462206.post-3992226397490897300' source='http://www.blogger.com/feeds/13462206/posts/default/3992226397490897300' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-799738138'/></entry><entry><id>tag:blogger.com,1999:blog-13462206.post-7799287640297454182</id><published>2011-06-30T16:56:57.446+02:00</published><updated>2011-06-30T16:56:57.446+02:00</updated><title type='text'>Le protocole SSH est, à ma connaissance,  dit « sû...</title><content type='html'>Le protocole SSH est, à ma connaissance,  dit « sûr » algorithmiquement. Ses vulnérabilités proviennent entres autres de défauts d’implantations, de l’acceptation de choses obsolètes pour raison de compatibilité (tel que le protocole 1, de vieux algorithmes, …). Le hardening et l’utilisation de la version la plus récente permettent de restreindre au mieux la surface d’attaque. Toutefois, l’erreur (ou l’oubli) étant humaine ou encore l’apparition de vulnérabilités méconnues n’étant pas à exclure, la furtivité permet de cacher toute information susceptible de mettre un attaquant sur la voie d’une vulnérabilité potentielle du protocole mis en place.&lt;br /&gt;Les attaques contre le protocole SSH sont multiples et il est difficile de dresser une liste représentative. Pour fixer les idées quant à ces attaques possibles contre openssh, par exemple, le site suivant fait un résumé de l’historique des vulnérabilités liées aux versions obsolètes : &lt;a href="http://www.openssh.org/fr/security.html" rel="nofollow"&gt;http://www.openssh.org/fr/security.html&lt;/a&gt;. Le chiffrement du handshake vise à éviter qu’un attaquant puisse facilement identifier une version obsolète du protocole utilisé, un chiffrement faible ou autre information qui permettrait d’utiliser une application automatisant l’attaque.&lt;br /&gt;&lt;br /&gt;En espérant que cela réponde à vos interrogations.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3992226397490897300/comments/default/7799287640297454182'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3992226397490897300/comments/default/7799287640297454182'/><link rel='alternate' type='text/html' href='http://www.citadelle-electronique.net/2011/06/furtivite-et-hardening-avec-un.html?showComment=1309445817446#c7799287640297454182' title=''/><author><name>Anne Gosselin</name><uri>http://www.blogger.com/profile/18147474327369338111</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.citadelle-electronique.net/2011/06/furtivite-et-hardening-avec-un.html' ref='tag:blogger.com,1999:blog-13462206.post-3992226397490897300' source='http://www.blogger.com/feeds/13462206/posts/default/3992226397490897300' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1235998680'/></entry><entry><id>tag:blogger.com,1999:blog-13462206.post-4461300654654340884</id><published>2011-06-17T09:31:24.932+02:00</published><updated>2011-06-17T09:31:24.932+02:00</updated><title type='text'>Merci pour ce billet très intéressant, j&amp;#39;ai ce...</title><content type='html'>Merci pour ce billet très intéressant, j&amp;#39;ai cependant une question sur la détermination de la version du SSH et sur l&amp;#39;écoute du Handshake.&lt;br /&gt;&lt;br /&gt;A ma connaissance, seule la version 1 du SSH est vulnérable et à moins d&amp;#39;utiliser des clés de chiffrement très faibles (asymétrique pour l&amp;#39;échange de clé et symétrique pour le chiffrement des flux), il est quasi-impossible d’arriver au bout de ce protocole.&lt;br /&gt;&lt;br /&gt;Il est sûr que l&amp;#39;OTP apporte une couche de sécurité supplémentaire, mais je souhaiterais savoir qu&amp;#39;elles sont les attaques réelles possibles contre ce protocole.&lt;br /&gt;&lt;br /&gt;Merci !</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3992226397490897300/comments/default/4461300654654340884'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3992226397490897300/comments/default/4461300654654340884'/><link rel='alternate' type='text/html' href='http://www.citadelle-electronique.net/2011/06/furtivite-et-hardening-avec-un.html?showComment=1308295884932#c4461300654654340884' title=''/><author><name>chevalier3as</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.citadelle-electronique.net/2011/06/furtivite-et-hardening-avec-un.html' ref='tag:blogger.com,1999:blog-13462206.post-3992226397490897300' source='http://www.blogger.com/feeds/13462206/posts/default/3992226397490897300' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-626635301'/></entry><entry><id>tag:blogger.com,1999:blog-13462206.post-5640668043083461197</id><published>2011-06-12T11:46:25.680+02:00</published><updated>2011-06-12T11:46:25.680+02:00</updated><title type='text'>very good interesting post</title><content type='html'>very good interesting post</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/7602282005251493655/comments/default/5640668043083461197'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/7602282005251493655/comments/default/5640668043083461197'/><link rel='alternate' type='text/html' href='http://www.citadelle-electronique.net/2009/06/2eme-jour-sstic-rennes.html?showComment=1307871985680#c5640668043083461197' title=''/><author><name>mobile tracker</name><uri>http://www.mobilephone-tracker.com/</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.citadelle-electronique.net/2009/06/2eme-jour-sstic-rennes.html' ref='tag:blogger.com,1999:blog-13462206.post-7602282005251493655' source='http://www.blogger.com/feeds/13462206/posts/default/7602282005251493655' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1239397033'/></entry><entry><id>tag:blogger.com,1999:blog-13462206.post-7464383946468823647</id><published>2011-03-30T19:06:51.263+02:00</published><updated>2011-03-30T19:06:51.263+02:00</updated><title type='text'>Merci pour votre commentaire. Je suis complétement...</title><content type='html'>Merci pour votre commentaire. Je suis complétement en phase avec l&amp;#39;approche Open. Par contre je préfère utiliser soit TOTP, HOTP voir OCRA. Selon moi mOTP devient obselète (Utilisation de MD5). Par contre, c&amp;#39;est vrai, il y a beaucoup de support de mOTP.&lt;br /&gt;Pour info vous pouvez utiliser la Class http://www.multiotp.net/ pour implémenter les algos de OATH.&lt;br /&gt;&lt;br /&gt;Sylvain</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3025841000610562507/comments/default/7464383946468823647'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3025841000610562507/comments/default/7464383946468823647'/><link rel='alternate' type='text/html' href='http://www.citadelle-electronique.net/2011/03/hack-rsa-securid-lhistoire-nest-pas.html?showComment=1301504811263#c7464383946468823647' title=''/><author><name>Sylvain Maret</name><uri>http://www.blogger.com/profile/04336297227186666432</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='04701856898342055395'/><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://3.bp.blogspot.com/_QntNf2b8LN8/SvG_8y8U6DI/AAAAAAAAHcg/k31ODCy9euU/S220/sylvain+cool+3.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.citadelle-electronique.net/2011/03/hack-rsa-securid-lhistoire-nest-pas.html' ref='tag:blogger.com,1999:blog-13462206.post-3025841000610562507' source='http://www.blogger.com/feeds/13462206/posts/default/3025841000610562507' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1517235644'/></entry><entry><id>tag:blogger.com,1999:blog-13462206.post-5719419822189518545</id><published>2011-03-30T17:14:07.630+02:00</published><updated>2011-03-30T17:14:07.630+02:00</updated><title type='text'>Hello, de mon côté, je privilégie depuis longtemps...</title><content type='html'>Hello, de mon côté, je privilégie depuis longtemps la génération de &amp;quot;passcode&amp;quot; en utilisant le protocole ouvert mOTP, cela au travers d&amp;#39;une application installable sur Android, iPhone, Windows Mobile, Java, etc.&lt;br /&gt;Avec mOTP (motp.sf.net), le PIN doit être entré sur le téléphone pour générer le passcode correct, ainsi il ne passe jamais en clair ;-)&lt;br /&gt;&lt;br /&gt;En plus, il est supporté par multiOTP.net, implémentation libre côté serveur en PHP, alors pourquoi s&amp;#39;en priver ?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3025841000610562507/comments/default/5719419822189518545'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3025841000610562507/comments/default/5719419822189518545'/><link rel='alternate' type='text/html' href='http://www.citadelle-electronique.net/2011/03/hack-rsa-securid-lhistoire-nest-pas.html?showComment=1301498047630#c5719419822189518545' title=''/><author><name>SorG</name><uri>http://www.blogger.com/profile/18230323987748255495</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.citadelle-electronique.net/2011/03/hack-rsa-securid-lhistoire-nest-pas.html' ref='tag:blogger.com,1999:blog-13462206.post-3025841000610562507' source='http://www.blogger.com/feeds/13462206/posts/default/3025841000610562507' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1557719625'/></entry><entry><id>tag:blogger.com,1999:blog-13462206.post-3664451898112006037</id><published>2011-03-23T18:15:02.722+01:00</published><updated>2011-03-23T18:15:02.722+01:00</updated><title type='text'>C&amp;#39;est effectivement une piste qui donne du sen...</title><content type='html'>C&amp;#39;est effectivement une piste qui donne du sens .....&lt;br /&gt;&lt;br /&gt;Mais pas facile de savoir vraiment la réalité dans cette affaire.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/4326617076639974125/comments/default/3664451898112006037'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/4326617076639974125/comments/default/3664451898112006037'/><link rel='alternate' type='text/html' href='http://www.citadelle-electronique.net/2011/03/changement-de-paradigme.html?showComment=1300900502722#c3664451898112006037' title=''/><author><name>Sylvain Maret</name><uri>http://www.blogger.com/profile/04336297227186666432</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='04701856898342055395'/><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://3.bp.blogspot.com/_QntNf2b8LN8/SvG_8y8U6DI/AAAAAAAAHcg/k31ODCy9euU/S220/sylvain+cool+3.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.citadelle-electronique.net/2011/03/changement-de-paradigme.html' ref='tag:blogger.com,1999:blog-13462206.post-4326617076639974125' source='http://www.blogger.com/feeds/13462206/posts/default/4326617076639974125' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1517235644'/></entry><entry><id>tag:blogger.com,1999:blog-13462206.post-306130695787191936</id><published>2011-03-23T18:05:32.222+01:00</published><updated>2011-03-23T18:05:32.222+01:00</updated><title type='text'>Je trouve l&amp;#39;hypothèse avec la directive FFIEC ...</title><content type='html'>Je trouve l&amp;#39;hypothèse avec la directive FFIEC très intéressante. Merci de l&amp;#39;avoir soumise !</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/4326617076639974125/comments/default/306130695787191936'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/4326617076639974125/comments/default/306130695787191936'/><link rel='alternate' type='text/html' href='http://www.citadelle-electronique.net/2011/03/changement-de-paradigme.html?showComment=1300899932222#c306130695787191936' title=''/><author><name>Sportet</name><uri>http://www.blogger.com/profile/10786589723654267662</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.citadelle-electronique.net/2011/03/changement-de-paradigme.html' ref='tag:blogger.com,1999:blog-13462206.post-4326617076639974125' source='http://www.blogger.com/feeds/13462206/posts/default/4326617076639974125' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1181961698'/></entry><entry><id>tag:blogger.com,1999:blog-13462206.post-280433284699333513</id><published>2010-09-24T03:20:03.164+02:00</published><updated>2010-09-24T03:20:03.164+02:00</updated><title type='text'>test avec coche email de google ?????</title><content type='html'>test avec coche email de google ?????</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3446629208538492268/comments/default/280433284699333513'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3446629208538492268/comments/default/280433284699333513'/><link rel='alternate' type='text/html' href='http://www.citadelle-electronique.net/2010/06/voila-maintenant-plus-dun-mois-que-je.html?showComment=1285291203164#c280433284699333513' title=''/><author><name>Sylvain Maret</name><uri>http://www.blogger.com/profile/04336297227186666432</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='04701856898342055395'/><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://3.bp.blogspot.com/_QntNf2b8LN8/SvG_8y8U6DI/AAAAAAAAHcg/k31ODCy9euU/S220/sylvain+cool+3.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.citadelle-electronique.net/2010/06/voila-maintenant-plus-dun-mois-que-je.html' ref='tag:blogger.com,1999:blog-13462206.post-3446629208538492268' source='http://www.blogger.com/feeds/13462206/posts/default/3446629208538492268' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1517235644'/></entry><entry><id>tag:blogger.com,1999:blog-13462206.post-7257038430337557716</id><published>2010-09-24T03:19:25.120+02:00</published><updated>2010-09-24T03:19:25.120+02:00</updated><title type='text'>test avec OpenID Clavid</title><content type='html'>test avec OpenID Clavid</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3446629208538492268/comments/default/7257038430337557716'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3446629208538492268/comments/default/7257038430337557716'/><link rel='alternate' type='text/html' href='http://www.citadelle-electronique.net/2010/06/voila-maintenant-plus-dun-mois-que-je.html?showComment=1285291165120#c7257038430337557716' title=''/><author><name>smaret</name><uri>http://smaret.clavid.ch/</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='15908526881261538232'/><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/openid16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.citadelle-electronique.net/2010/06/voila-maintenant-plus-dun-mois-que-je.html' ref='tag:blogger.com,1999:blog-13462206.post-3446629208538492268' source='http://www.blogger.com/feeds/13462206/posts/default/3446629208538492268' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-799738138'/></entry><entry><id>tag:blogger.com,1999:blog-13462206.post-4404822866545807023</id><published>2010-09-24T03:18:45.365+02:00</published><updated>2010-09-24T03:18:45.365+02:00</updated><title type='text'>test</title><content type='html'>test</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3446629208538492268/comments/default/4404822866545807023'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3446629208538492268/comments/default/4404822866545807023'/><link rel='alternate' type='text/html' href='http://www.citadelle-electronique.net/2010/06/voila-maintenant-plus-dun-mois-que-je.html?showComment=1285291125365#c4404822866545807023' title=''/><author><name>Sylvain Maret</name><uri>http://www.blogger.com/profile/04336297227186666432</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='04701856898342055395'/><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://3.bp.blogspot.com/_QntNf2b8LN8/SvG_8y8U6DI/AAAAAAAAHcg/k31ODCy9euU/S220/sylvain+cool+3.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.citadelle-electronique.net/2010/06/voila-maintenant-plus-dun-mois-que-je.html' ref='tag:blogger.com,1999:blog-13462206.post-3446629208538492268' source='http://www.blogger.com/feeds/13462206/posts/default/3446629208538492268' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1517235644'/></entry><entry><id>tag:blogger.com,1999:blog-13462206.post-8583360137807412842</id><published>2010-09-24T03:14:56.573+02:00</published><updated>2010-09-24T03:14:56.573+02:00</updated><title type='text'>Test</title><content type='html'>Test</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3446629208538492268/comments/default/8583360137807412842'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3446629208538492268/comments/default/8583360137807412842'/><link rel='alternate' type='text/html' href='http://www.citadelle-electronique.net/2010/06/voila-maintenant-plus-dun-mois-que-je.html?showComment=1285290896573#c8583360137807412842' title=''/><author><name>smaret</name><uri>http://smaret.clavid.ch/</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='15908526881261538232'/><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/openid16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.citadelle-electronique.net/2010/06/voila-maintenant-plus-dun-mois-que-je.html' ref='tag:blogger.com,1999:blog-13462206.post-3446629208538492268' source='http://www.blogger.com/feeds/13462206/posts/default/3446629208538492268' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-799738138'/></entry><entry><id>tag:blogger.com,1999:blog-13462206.post-3665205099262177835</id><published>2010-04-19T21:33:53.334+02:00</published><updated>2010-04-19T21:33:53.334+02:00</updated><title type='text'>Bonjour,
C&amp;#39;est effectivement un sujet à la mod...</title><content type='html'>Bonjour,&lt;br /&gt;C&amp;#39;est effectivement un sujet à la mode. Je viens d&amp;#39;ailleurs de travailler dessus: l&amp;#39;utilisation d&amp;#39;un Trusted Platform Module dans le cadre de l&amp;#39;authentification forte (http://infond.blogspot.com).&lt;br /&gt;Merci pour ces infos.&lt;br /&gt;t0ka7a</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/7847386876389254141/comments/default/3665205099262177835'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/7847386876389254141/comments/default/3665205099262177835'/><link rel='alternate' type='text/html' href='http://www.citadelle-electronique.net/2010/04/democratisation-de-lauthentification.html?showComment=1271705633334#c3665205099262177835' title=''/><author><name>t0ka7a</name><uri>http://www.blogger.com/profile/08174105297955674077</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.citadelle-electronique.net/2010/04/democratisation-de-lauthentification.html' ref='tag:blogger.com,1999:blog-13462206.post-7847386876389254141' source='http://www.blogger.com/feeds/13462206/posts/default/7847386876389254141' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1103094348'/></entry><entry><id>tag:blogger.com,1999:blog-13462206.post-5062934267843025105</id><published>2010-04-16T13:03:17.997+02:00</published><updated>2010-04-16T13:03:17.997+02:00</updated><title type='text'>Pour information, j&amp;#39;ai eu un contact avec le c...</title><content type='html'>Pour information, j&amp;#39;ai eu un contact avec le constructeur. La nouvelle version du Soft Token permer maintenant d&amp;#39;initialiser le &amp;quot;seed&amp;quot; en mode sécurisé avec le protocole SSL/TLS.&lt;br /&gt;&lt;br /&gt;La pression ca fonctionne :-)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3301109784469864180/comments/default/5062934267843025105'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3301109784469864180/comments/default/5062934267843025105'/><link rel='alternate' type='text/html' href='http://www.citadelle-electronique.net/2009/12/otp-pour-iphone-une-retour-dexperience.html?showComment=1271415797997#c5062934267843025105' title=''/><author><name>Sylvain Maret</name><uri>http://www.blogger.com/profile/04336297227186666432</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='04701856898342055395'/><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://3.bp.blogspot.com/_QntNf2b8LN8/SvG_8y8U6DI/AAAAAAAAHcg/k31ODCy9euU/S220/sylvain+cool+3.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.citadelle-electronique.net/2009/12/otp-pour-iphone-une-retour-dexperience.html' ref='tag:blogger.com,1999:blog-13462206.post-3301109784469864180' source='http://www.blogger.com/feeds/13462206/posts/default/3301109784469864180' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1517235644'/></entry><entry><id>tag:blogger.com,1999:blog-13462206.post-2539308448684158165</id><published>2010-04-16T12:45:19.211+02:00</published><updated>2010-04-16T12:45:19.211+02:00</updated><title type='text'>Certes, le choix du HTTP est à...comprendre mais i...</title><content type='html'>Certes, le choix du HTTP est à...comprendre mais il offre toutefois l&amp;#39;avantage d&amp;#39;être un problème très &amp;quot;solutionnable&amp;quot; avec la pression adéquate (pot de vin, chantage, menace, bière, pizza, etc.) si le reste de la solution répond au besoin.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3301109784469864180/comments/default/2539308448684158165'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3301109784469864180/comments/default/2539308448684158165'/><link rel='alternate' type='text/html' href='http://www.citadelle-electronique.net/2009/12/otp-pour-iphone-une-retour-dexperience.html?showComment=1271414719211#c2539308448684158165' title=''/><author><name>Starbuck</name><uri>http://www.blogger.com/profile/05606277016159112012</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.citadelle-electronique.net/2009/12/otp-pour-iphone-une-retour-dexperience.html' ref='tag:blogger.com,1999:blog-13462206.post-3301109784469864180' source='http://www.blogger.com/feeds/13462206/posts/default/3301109784469864180' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-102626543'/></entry><entry><id>tag:blogger.com,1999:blog-13462206.post-8810814574828355606</id><published>2010-04-14T07:16:33.317+02:00</published><updated>2010-04-14T07:16:33.317+02:00</updated><title type='text'>Personnellement le fait que ca soit en HTTP serait...</title><content type='html'>Personnellement le fait que ca soit en HTTP serait pour moi rédibitoire.....</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3301109784469864180/comments/default/8810814574828355606'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3301109784469864180/comments/default/8810814574828355606'/><link rel='alternate' type='text/html' href='http://www.citadelle-electronique.net/2009/12/otp-pour-iphone-une-retour-dexperience.html?showComment=1271222193317#c8810814574828355606' title=''/><author><name>S.</name><uri>http://www.blogger.com/profile/16195172180160128332</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='13842610793121216870'/><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.citadelle-electronique.net/2009/12/otp-pour-iphone-une-retour-dexperience.html' ref='tag:blogger.com,1999:blog-13462206.post-3301109784469864180' source='http://www.blogger.com/feeds/13462206/posts/default/3301109784469864180' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-670632587'/></entry><entry><id>tag:blogger.com,1999:blog-13462206.post-718572798148399139</id><published>2009-12-08T10:44:39.991+01:00</published><updated>2009-12-08T10:44:39.991+01:00</updated><title type='text'>Bonjour,

Je viens de découvrir votre blogue ce ma...</title><content type='html'>Bonjour,&lt;br /&gt;&lt;br /&gt;Je viens de découvrir votre blogue ce matin. En lisant ce post, la partie suivante m&amp;#39;a interpellée : &lt;br /&gt;&lt;i&gt;&amp;quot;Il sera possible pour les entreprises et particuliers d&amp;#39;utiliser cet authentifieur SuisseID pour avoir un OpenID&amp;quot;&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;Auriez-vous plus d&amp;#39;information technique à ce sujet?&lt;br /&gt;&lt;br /&gt;Meilleures salutations,&lt;br /&gt;G.B.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/5177712235785355832/comments/default/718572798148399139'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/5177712235785355832/comments/default/718572798148399139'/><link rel='alternate' type='text/html' href='http://www.citadelle-electronique.net/2009/11/preuve-didentite-electronique-suisseid.html?showComment=1260265479991#c718572798148399139' title=''/><author><name>spam</name><uri>http://www.blogger.com/profile/17066777997234509740</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.citadelle-electronique.net/2009/11/preuve-didentite-electronique-suisseid.html' ref='tag:blogger.com,1999:blog-13462206.post-5177712235785355832' source='http://www.blogger.com/feeds/13462206/posts/default/5177712235785355832' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1923205492'/></entry><entry><id>tag:blogger.com,1999:blog-13462206.post-5460617200839534610</id><published>2009-11-26T17:24:05.877+01:00</published><updated>2009-11-26T17:24:05.877+01:00</updated><title type='text'>Merci Sylvain.

We are working on two pilots right...</title><content type='html'>Merci Sylvain.&lt;br /&gt;&lt;br /&gt;We are working on two pilots right now with pre-selected business customers. They like the two-factor security credential, and the fact that the LoginTC federates with Internet SSO apps. &lt;br /&gt;&lt;br /&gt;We are also open to partnerships and/or distributors in Europe. We understand Europeans are more progressive in the federation field, and a 2FA federated credential may be the extra peace of mind they may embrace.&lt;br /&gt;&lt;br /&gt;Have you tried the LoginTC? Go and register for a demo test with your own USB flash drive at:&lt;br /&gt;&lt;br /&gt;http://www.logintc.com/registration&lt;br /&gt;&lt;br /&gt;and experience how Google apps and SugarCRM federate with your USB drive.&lt;br /&gt;&lt;br /&gt;Hernan</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/2613972745774970535/comments/default/5460617200839534610'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/2613972745774970535/comments/default/5460617200839534610'/><link rel='alternate' type='text/html' href='http://www.citadelle-electronique.net/2009/11/saml-vs-openid-soyons-pragmatique-et.html?showComment=1259252645877#c5460617200839534610' title=''/><author><name>hmatute</name><uri>http://www.blogger.com/profile/14060609828804827166</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.citadelle-electronique.net/2009/11/saml-vs-openid-soyons-pragmatique-et.html' ref='tag:blogger.com,1999:blog-13462206.post-2613972745774970535' source='http://www.blogger.com/feeds/13462206/posts/default/2613972745774970535' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1728986583'/></entry><entry><id>tag:blogger.com,1999:blog-13462206.post-8531329708839279048</id><published>2009-11-25T23:26:15.037+01:00</published><updated>2009-11-25T23:26:15.037+01:00</updated><title type='text'>Hello Herman,

Thanks for your comment. And bravo ...</title><content type='html'>Hello Herman,&lt;br /&gt;&lt;br /&gt;Thanks for your comment. And bravo for your services using SAML and Strong Authentication.&lt;br /&gt;&lt;br /&gt;Do you have a lot of users now ?&lt;br /&gt;&lt;br /&gt;Sylvain</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/2613972745774970535/comments/default/8531329708839279048'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/2613972745774970535/comments/default/8531329708839279048'/><link rel='alternate' type='text/html' href='http://www.citadelle-electronique.net/2009/11/saml-vs-openid-soyons-pragmatique-et.html?showComment=1259187975037#c8531329708839279048' title=''/><author><name>Sylvain Maret</name><uri>http://www.blogger.com/profile/04336297227186666432</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='04701856898342055395'/><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://3.bp.blogspot.com/_QntNf2b8LN8/SvG_8y8U6DI/AAAAAAAAHcg/k31ODCy9euU/S220/sylvain+cool+3.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.citadelle-electronique.net/2009/11/saml-vs-openid-soyons-pragmatique-et.html' ref='tag:blogger.com,1999:blog-13462206.post-2613972745774970535' source='http://www.blogger.com/feeds/13462206/posts/default/2613972745774970535' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1517235644'/></entry><entry><id>tag:blogger.com,1999:blog-13462206.post-1705256634356686045</id><published>2009-11-25T16:14:23.055+01:00</published><updated>2009-11-25T16:14:23.055+01:00</updated><title type='text'>I totally agree with Jason with respect to federat...</title><content type='html'>I totally agree with Jason with respect to federated id and the use of internet applications in the cloud with a single credential. The risk, as he points out, is the vulnerability of maintaining the traditional userid/password paradigm and exposing the risk of identity or document theft across multiple domains.&lt;br /&gt;&lt;br /&gt;We have developed a comprehensive federated solution with the LoginTC (www.logintc.com). Its ability to provide roaming users with a two-factor authentication, combined with SAML-enabled capabilities makes it the most comprehensive solution in the marketplace. The user only needs to enable a USB flash drive.&lt;br /&gt;&lt;br /&gt;Looking forward, it will be extremely beneficial to ensure that not only corporate business access is achieved, but personal online banking and online payment can also be integrated. &lt;br /&gt;&lt;br /&gt;Great insight from Jason.&lt;br /&gt;&lt;br /&gt;Hernan M.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/2613972745774970535/comments/default/1705256634356686045'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/2613972745774970535/comments/default/1705256634356686045'/><link rel='alternate' type='text/html' href='http://www.citadelle-electronique.net/2009/11/saml-vs-openid-soyons-pragmatique-et.html?showComment=1259162063055#c1705256634356686045' title=''/><author><name>hmatute</name><uri>http://www.blogger.com/profile/14060609828804827166</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.citadelle-electronique.net/2009/11/saml-vs-openid-soyons-pragmatique-et.html' ref='tag:blogger.com,1999:blog-13462206.post-2613972745774970535' source='http://www.blogger.com/feeds/13462206/posts/default/2613972745774970535' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1728986583'/></entry></feed>
